[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Microsoft ASP.NET Core Security Feature Bypass Vulnerability - CVE-2020-1045

ID: oval:org.secpod.oval:def:65365Date: (C)2020-09-09   (M)2024-01-08
Class: VULNERABILITYFamily: windows




A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded. The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.

Platform:
Microsoft Windows 7
Microsoft Windows 8.1
Microsoft Windows 10
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Product:
Microsoft ASP .NET core 2.1
Microsoft ASP .NET core 3.1
Reference:
CVE-2020-1045
CVE    1
CVE-2020-1045
CPE    2
cpe:/a:microsoft:asp_.net_core:2.1:::x64
cpe:/a:microsoft:asp_.net_core:2.1:::x86

© SecPod Technologies